The Bitcoin ecosystem has faced another attack on self-hosting infrastructure services following the recent Coldcard hack, which reportedly resulted in the theft of over 1,700 $BTC according to Galaxy Research.
BTCPay Server, an open-source, self-hosted cryptocurrency payment processor, announced it is facing an ongoing attack by unknown threat actors targeting its codebase.
On social media, the BTCPay Server team emphasized that "a critical vulnerability in BTCPay Server is being actively exploited, which can lead to loss of funds."
This vulnerability was reported by the Bitcoin Red Team — a volunteer group of security experts who, following the Coldcard hack, have already discovered thousands of vulnerabilities in hundreds of open-source projects.
"Please update your BTCPay Server to version 2.4.2 by going to the 'Admin Dashboard' -> 'Server' -> 'Maintenance' -> 'Update' and confirming that version 2.4.2 is displayed in the footer. If you cannot update immediately, shut down your BTCPay Server to prevent unauthorized access until you can perform the update," the BTCPay Server team advised.
Furthermore, the project's developers urged users to update the macaroons and macaroons.db — two key server files; update authentication strings; and move any funds if they are stored in a hot wallet generated by BTCPay.
Although details of this vulnerability have not been publicly disclosed, at least two instances of fund theft are known. Zack Herbert, co-founder and CEO of Foundation, the developer of the Passport Prime device, reported that their node was drained overnight.
Hodlonaut also discovered that funds from the Lightning Citadel 21 node were stolen, noting that it did not hold many funds due to precautions related to the potential activation of BIP-110.
He emphasized that this attack appears to be targeted and aimed at the "heart" of the Bitcoin social layer. "Coldcard and BTCPayserver. These are tools for enthusiasts and hardcore users, used by people who live and breathe Bitcoin. This doesn't look like a coincidence," he concluded.








